HELK – Open Source Threat Hunting Platform
ID: 28d6493b-29e7-5de2-8cba-e831ddee9960
STIX ID: report--28d6493b-29e7-5de2-8cba-e831ddee9960
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that extracts credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries and browsing history from major Windows browsers. It implements an App‑Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple operational evasion techniques, and outputs structured JSON—making it useful for red-team testing but also a high-risk capability if used by malicious actors to enable lateral movement or cloud account takeover.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
